PT-2022-3529 · Secheron · Secheron Sepcos
Anthony Candarini
+3
·
Published
2022-05-10
·
Updated
2022-07-05
·
CVE-2022-1667
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Secheron SEPCOS Single Package relay control and protection software (affected versions not specified)
Description
The issue is related to the incorrect implementation of a sequence of actions in the software. It allows a remote attacker to reboot the device by running a JS function or loading a corresponding PHP script. This can be achieved by directly running a JS function to reboot the PLC, for example, from the browser console, or by loading the browser-accessible PHP script.
Recommendations
As a temporary workaround, consider disabling the JS function that allows rebooting the device until a patch is available.
Restrict access to the PHP script that can reboot the device to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Secheron Sepcos